跳转至主要内容
AskAuthor

This summary is translated for accessibility. The English version below is legally binding.

Read the legally binding English version

Plain-language summary

[REVIEW] What this page is

This summary explains, in plain language, how AskAuthor handles your personal data. The full English policy below is what legally binds us.

[REVIEW] What we collect

We collect the email you sign in with (via magic link or Google), Google profile details when you use Google sign-in, profile settings you choose, anything you post on the platform (questions, answers, comments, profile information), and payment metadata from Stripe — never your card numbers. Plausible gives us anonymous aggregate traffic numbers. PostHog, Sentry, and Cloudflare Turnstile help us improve, debug, and protect the product; optional analytics and diagnostics are consent-gated where required.

[REVIEW] How we use it

We use your data to run the service: to sign you in, show your profile, route questions to authors, process payments, send transactional emails (receipts, notifications), and keep the platform safe. We do not sell your data. We do not target ads. We do not build behavioral profiles of you.

[REVIEW] Who we share with

Supabase hosts your account data. Stripe processes payments, subscriptions, Connect payouts, and payment disputes. Resend delivers emails. Vercel serves the site. Cloudflare Turnstile blocks bots. PostHog and Sentry support consent-gated analytics and diagnostics. Each one processes data so AskAuthor can operate the service.

[REVIEW] Your rights

You can ask for a copy of your data, fix inaccuracies, delete your account, or port your data elsewhere. EU residents have full GDPR rights including lodging a complaint with a data protection authority. Brazilian residents have LGPD rights. California residents have CCPA rights and we do not sell personal information. Email privacy@askauthor.io to exercise any right — we reply within 30 days (15 business days for LGPD).

[REVIEW] Retention and deletion

Your content stays until you delete your account. Account deletion has a 7-day cooling-off period; after that, profile data and engagement rows are removed, reader questions and comments are anonymized, author replies are redacted, and active personal data is deleted within 30 days where deletion is legally and technically available. Financial records are kept for up to 7 years because tax, accounting, and payment-dispute rules require it.

[REVIEW] Children

AskAuthor is not for anyone under 13. Ages 13–18 should have parental permission.

[REVIEW] Contact

privacy@askauthor.io for any privacy question or request.

Privacy Policy

Last updated: May 10, 2026

AskAuthor (“we,” “us,” or “our”) operates the AskAuthor platform, which connects readers with authors through Q&A. This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have. We write this in plain English because privacy policies should actually be readable.

Data Controller

The data controller responsible for your personal information under the GDPR, UK GDPR, LGPD, and equivalent privacy laws is AskAuthor, operated by A. C. Monteiro as a U.S. sole proprietorship.

  • Controller: AskAuthor, operated by A. C. Monteiro as a sole proprietorship.
  • Privacy contact: privacy@askauthor.io — primary channel for privacy questions and data-rights requests.
  • General support contact: support@askauthor.io.
  • EU/UK representative (GDPR Art. 27 / UK GDPR): Not currently appointed. Current launch processing is treated as occasional and low-risk; we will designate a representative if EU/UK data processing volume or nature crosses the Art. 27 threshold.
  • Data Protection Officer (GDPR Art. 37): Not required at current scale because AskAuthor is not a public authority, does not conduct large-scale systematic monitoring, and does not process special-category data at large scale. We will reassess as the service grows.

1. What We Collect

Account information

AskAuthor supports two authentication methods: magic link email authentication (passwordless, via Supabase Auth) and Google OAuth (when enabled). When you sign in with a magic link, we collect only your email address. When you sign in with Google, we receive your name, email address, and profile photo from Google. We do not receive or store any passwords. We also store profile settings you choose to add or change, such as display name, avatar, author profile details, email preferences, country-visibility preferences, and account status.

Content you submit

Questions you ask, answers you post, and any other content you submit to the platform are stored in our database. Public content is visible to other users.

Payment metadata

If you make a payment (including Spotlight, tips, platform support, or Pro subscriptions), Stripe processes your payment. We never see or store your card number, CVV, or full billing address. We receive payment status, Stripe transaction identifiers, receipts, amount and currency, payment type, and non-card metadata needed to fulfill the transaction, including any applicable Spotlight revenue split and payout-readiness status at the time of payment.

Analytics and diagnostics

We use Plausible Analytics to understand how people use AskAuthor. Plausible itself sets no cookies and collects no personal data — only aggregated, anonymized page-view statistics (e.g., how many people visited the homepage today). No IP addresses, device fingerprints, or cross-site tracking. Plausible loads only after you accept cookies via our consent banner; before consent, no analytics pings are sent from your browser. We also use consent-gated PostHog product analytics and Sentry error diagnostics as described below.

2. How We Use Your Information

  • Operate the platform — authenticate your account, display your profile, preserve your preferences, deliver questions and answers between readers and authors, and route moderation, copyright, support, and account-safety requests.
  • Process payments — coordinate with Stripe to fulfill paid transactions, apply the disclosed Spotlight split when relevant, and issue receipts.
  • Send email — account confirmations, new question notifications, payment receipts, author growth tips, product announcements, and newsletters where enabled. Non-essential emails include unsubscribe or preference controls.
  • Improve the service — use aggregated, anonymized analytics to understand which features are useful and where we can do better.
  • Comply with legal obligations — retain financial records as required by law, process DMCA notices or counter-notices, and respond to lawful government requests.

We do not sell your personal information. We do not use your data for advertising or behavioral profiling.

3. Third-Party Services

We use the following third-party services to operate AskAuthor. Each is a data processor acting on our instructions:

Supabase

Our database and authentication provider. Your account data and content are stored on Supabase servers in the United States. Supabase is SOC 2 Type II certified. Supabase Privacy Policy.

Stripe

Payment processing. Stripe is PCI DSS Level 1 certified. Card data never touches our servers. Stripe Privacy Policy.

Resend

Transactional email delivery (account notifications, receipts). We share only your email address with Resend for delivery purposes. Resend Privacy Policy.

Plausible Analytics

Privacy-first analytics hosted on EU servers. Plausible does not set cookies or collect personal data, but we still load it only after you grant cookie consent via our banner. Plausible Privacy Policy.

Vercel

Hosting and deployment platform. Your requests are routed through Vercel's edge network. Vercel may process IP addresses, request metadata, and server-rendered page content. Vercel Privacy Policy.

Cloudflare (Turnstile)

Bot detection via Turnstile CAPTCHA widget. Processes IP addresses and browser signals to verify human users. Cloudflare Privacy Policy.

PostHog

We use PostHog for product analytics to understand how users interact with our platform. PostHog collects usage data including page views, feature interactions, and anonymized user identifiers. Data is processed in accordance with PostHog's privacy policy. PostHog Privacy Policy.

Sentry

We use Sentry for error monitoring and performance tracking. Sentry may capture technical information about errors you encounter, including device type, browser version, request context, user/account identifiers, and sampled error session replays with form inputs masked and media blocked to help us diagnose and fix issues. Sentry Privacy Policy.

4. Cookies

We use only strictly necessary session cookies. Specifically, Supabase sets sb-* cookies to maintain your authenticated session. These cookies are required for the platform to function — without them you cannot stay logged in.

In addition to essential cookies, we use analytics tools to understand how the platform is used and error monitoring to fix bugs. Plausible Analytics does not set cookies, but it — along with PostHog and Sentry — loads only after you grant consent via our cookie banner. PostHog and Sentry may set their own cookies as described in our Cookie Policy. Cloudflare Turnstile may also process browser signals for bot and abuse prevention on auth-sensitive flows. We do not set advertising or marketing cookies.

For full details, see our Cookie Policy.

5. Data Retention

  • Account and content data — retained until you delete your account. After the 7-day deletion cooling-off period, profile data and direct identifiers are removed from our active database within 30 days where deletion is legally and technically available.
  • Financial records — payment records are retained for 7 years as required by U.S. IRS regulations, payment disputes, accounting, and applicable tax law. Reader identifiers may be removed or anonymized where feasible while preserving legally required records.
  • Auth data — session tokens and authentication logs are deleted when your account is deleted or upon session expiry.
  • Analytics and diagnostics data — Plausible stores only anonymized, aggregated statistics with no retention link to any individual. Consent-gated PostHog and Sentry records are retained according to their configured retention settings and deleted or anonymized when no longer needed for product analytics, security, or diagnostics.

6. Account Deletion

You can delete your account at any time from your account settings. When you do:

  • Your profile is removed, and your public content is anonymized or redacted so it no longer identifies you.
  • Your profile, bookmarks, notifications, and engagement rows are removed from the platform after the 7-day cooling-off period.
  • Reader questions, non-author replies, and comments are anonymized; author replies are redacted so they no longer identify you while preserving Q&A thread integrity.
  • Financial records required by law or payment processors are retained for up to 7 years and anonymized where feasible.

If you cannot access your account settings or prefer to make a manual deletion request, email privacy@askauthor.io with the subject line “Account Deletion Request.” We will process it within 30 days.

7. Data Security

We take reasonable measures to protect your data. All data in transit is encrypted over HTTPS. Data at rest is encrypted via Supabase's encrypted storage layer. Payment data is handled exclusively by Stripe, which maintains PCI DSS Level 1 compliance. No method of transmission or storage is 100% secure; if you believe your account has been compromised, contact us immediately at privacy@askauthor.io.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users without undue delay. Where required by applicable law (including GDPR Article 33), we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Notification will include the nature of the breach, the likely consequences, and the measures taken or proposed to address it.

8. Affiliate Links

AskAuthor participates in affiliate programs with Amazon, Bookshop.org, and Libro.fm. When you click an affiliate link and make a purchase, we may earn a commission at no additional cost to you. These links are clearly identified. Transactions made through those links are subject to the privacy policies of Amazon, Bookshop.org, and Libro.fm respectively — we do not receive any personal data from those transactions.

9. GDPR — EU and EEA Users

If you are located in the European Union or European Economic Area, the following additional terms apply under the General Data Protection Regulation (GDPR).

Lawful basis for processing

  • Contract performance — processing your account data and payments is necessary to provide the service you signed up for.
  • Legitimate interest — security monitoring, fraud prevention, and service operations where our interest does not override your rights.
  • Legal obligation — retaining financial records as required by applicable law.
  • Consent — where you have explicitly opted in (for example, accepting the Terms of Service checkbox during signup, or subscribing to optional marketing emails). You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

Legal basis per processing activity

The following table summarizes the legal basis we rely on for each category of processing.

  • Account creation & authentication — Contract performance (GDPR Art. 6(1)(b)).
  • Publishing questions, answers, and profile content — Contract performance.
  • Payment processing (Stripe) — Contract performance and legal obligation (tax / accounting record retention).
  • Transactional email notifications — Contract performance (essential to operate your account).
  • Marketing or promotional email — Consent where required, or legitimate interest for service-related author/product updates where permitted. You may withdraw consent or opt out at any time via the unsubscribe link in every such email.
  • Security monitoring, abuse detection, rate limiting — Legitimate interest (GDPR Art. 6(1)(f)) in protecting the service and other users.
  • Cookieless product analytics (Plausible) — Not processing personal data; no lawful basis required.
  • Product analytics (PostHog) — Consent (GDPR Art. 6(1)(a)). PostHog only initializes after you accept cookies via the consent banner; before consent, no product-analytics events fire.
  • Error monitoring (Sentry) — Legitimate interest (GDPR Art. 6(1)(f)) in diagnosing bugs and keeping the service reliable. Session replay is sampled at 0% on normal sessions and triggers only when an error occurs; all form inputs are masked and media is blocked before the replay is recorded.
  • Bot / fraud prevention (Cloudflare Turnstile) — Legitimate interest.
  • Retention of financial records — Legal obligation (7-year IRS / tax retention).
  • Responding to lawful government or law-enforcement requests — Legal obligation.

Your rights

Under GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data (subject to legal retention obligations). We fulfill erasure requests within 30 days.
  • Data portability — receive your data in a structured, machine-readable format.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Objection — object to processing based on legitimate interests.
  • Lodge a complaint — you have the right to lodge a complaint with your local data protection supervisory authority if you believe we have violated your data protection rights.

No automated decision-making

We do not make automated decisions about you that produce legal or similarly significant effects. We do not engage in profiling.

Data transfers

Your data is stored on servers in the United States (Supabase). International data transfers are conducted under the EU-U.S. Data Privacy Framework, Standard Contractual Clauses (SCCs), or equivalent safeguards as required by GDPR Chapter V.

To exercise any GDPR right, email privacy@askauthor.io. We will respond within 30 days.

10. LGPD — Brazilian Users

If you are located in Brazil, the following additional terms apply under the Lei Geral de Proteção de Dados (LGPD).

Legal basis for processing

  • Contract performance — processing necessary to deliver the service you contracted for.
  • Legitimate interest — security, fraud prevention, and service operations.
  • Legal obligation — financial record retention as required by law.

Your rights under LGPD

  • Access — confirm whether we process your data and obtain a copy.
  • Correction — correct incomplete, inaccurate, or outdated data.
  • Deletion — request erasure of unnecessary or excessive data or data processed in violation of the LGPD.
  • Portability — receive your data in a portable format.
  • Objection — object to processing where it is not compliant with the LGPD.

International data transfers

Your data is stored on servers in the United States under data processing agreements that provide appropriate protections for international transfers as contemplated by the LGPD.

To exercise any LGPD right, email privacy@askauthor.io. We will respond within 15 business days.

11. CCPA — California Residents

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights.

We do not sell your personal information

AskAuthor does not sell, rent, or share your personal information with third parties for their own marketing or advertising purposes. We have not done so in the preceding 12 months. We honor all “Do Not Sell or Share My Personal Information” requests — though there is nothing to opt out of, since we do not sell data.

Categories of personal information collected

In the past 12 months we have collected:

  • Identifiers (name, email address, Google account ID)
  • Commercial information (payment transaction records via Stripe)
  • Internet/network activity (aggregated Plausible statistics, consent-gated PostHog analytics, Sentry diagnostics, and Cloudflare Turnstile abuse-prevention signals)
  • User-generated content (questions, answers, replies, comments, and profile data you submit)

Your rights as a California resident

  • Right to Know — request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete — request deletion of personal information we have collected about you, subject to certain exceptions.
  • Right to Correct — request correction of inaccurate personal information.
  • Right to Non-Discrimination — we will not discriminate against you for exercising any CCPA right.

To submit a CCPA request, email privacy@askauthor.io with the subject line “California Privacy Request.” We will respond within 45 days.

12. Children's Privacy (COPPA)

AskAuthor is not directed at children under the age of 13 and we do not knowingly collect personal information from children under 13. If you believe that a child under 13 has provided us with personal information, please contact us immediately at privacy@askauthor.io and we will delete that information as quickly as possible.

Users between 13 and 18 should have parental permission before using the service.

EEA, UK, and Swiss users:The General Data Protection Regulation (Article 8) requires that children under the age of 16 obtain verifiable consent from a parent or legal guardian before we process their personal data. Some EU member states have lowered this threshold (to as low as 13); the applicable age in your jurisdiction governs. If you are under the digital age of consent in your country, please do not create an account without a parent or guardian's involvement. If we become aware that we have collected personal data from a minor without the required consent, we will delete that data promptly. To report such a concern contact privacy@askauthor.io.

13. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes — those that meaningfully affect your rights or how we handle your data — we will provide at least 30 days' notice by posting the updated policy here and, where appropriate, notifying you by email. The “Last updated” date at the top of this page reflects when the current version was published. Continued use of AskAuthor after the effective date of any change constitutes your acceptance of the updated policy.

14. Contact Us

For questions, requests, or concerns about this Privacy Policy or how AskAuthor handles your data, please contact us at privacy@askauthor.io. For general support use support@askauthor.io; for legal notices unrelated to privacy or copyright use legal@askauthor.io. We are committed to resolving privacy concerns promptly and transparently.

AskAuthor

与作者和读者建立连接,提问、分享见解,一起聊聊你最爱的书。

关于我们

  • 公司介绍
  • 作者专区
  • 探索书籍
  • 联系我们
  • 支持 AskAuthor

法律条款

  • 服务条款
  • 隐私政策
  • Cookie 政策
  • DMCA
  • 不要出售我的信息

© 2026 AskAuthor。保留所有权利。